Use promo code:
CTA20

Expert Advice Community

Guest

Is it an NC

  Quote
Guest
Guest post Created:   Jan 12, 2016 Last commented:   Jan 12, 2016

Is it an NC

Hi Experts, I have a doubt on a situation, if NC can be given or not. An outsourcing company which provides training to other companies receives new contract of training every year. This contract contains list of student who will attend training. So, during audit, you find a requirement from customer that student information should be protected as per Govt. Procedure 888. The contract manager says, he does not know about Govt. procedure 888, and only read student names to be trained. All previous year contracts does not have this Govt. Procedure 888 requirement. Apparently, they do have their own procedure to protect student information.   Now, I say it is an NC as per 4.2(b), that they failed to identify contract requirement. As per my mate, it is not an NC, as they still have their own procedure to protect student information.   What is your view on this.   Thanks Prashsax
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Guest
DejanK Jan 12, 2016

I'm not sure if I understood your question well, but if the provider of training services has signed a contract with the customer where it has obliged to comply with certain requirement, then it must comply with it - otherwise this is a nonconformity.

The point is, a company must comply with all of these: ISO 27001 + laws & regulations + contractual obligations + its own policies and procedures.

This article can also help you: Major vs. minor nonconformities in the certification audit https://advisera.com/27001academy/blog/2014/06/02/major-vs-minor-nonconformities-in-the-certification-audit/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016

Suggested Topics

AAAA Created:   Mar 21, 2025 ISO 27001 & 22301
Replies: 0
0 0

UPDATE ADDRESS

Igor Created:   Mar 17, 2025 ISO 27001 & 22301
Replies: 0
0 0

Secure Development policy

Igor Created:   Feb 25, 2025 ISO 27001 & 22301
Replies: 0
0 0

Confidentiality Statement